News
14 min read

Why Mid-Sized Companies Can No Longer Ignore NIS2, and How CAVRIX Closes the Gap

The NIS2 grace period for the Mittelstand is over. Learn why managing directors are now personally liable and how CAVRIX closes your compliance gaps.

A modern mid-sized managing director looks decisively at a digital dashboard showing CAVRIX security status indicators on his tablet.
A modern mid-sized managing director looks decisively at a digital dashboard showing CAVRIX security status indicators on his tablet.

The New Cyber Reality: Why the NIS2 Implementation Act Forces the Mittelstand to Act

The German NIS2 Implementation Act officially came into force on 6 December 2025 without any transition periods. This puts around 30,000 German companies with 50 or more employees in front of a new regulatory reality. Those affected are no longer just classic large corporations or operators of critical infrastructure, but a significant share of the German Mittelstand. Anyone who ignores the statutory minimum requirements risks not only substantial fines for the business, but also faces a massively tightened personal liability. As the managing director of a mid-sized company, the law requires proactive action from you and your leadership team, along with seamless risk management across your IT infrastructure.

  • Affected sectors: The regulation applies across numerous industries above a threshold of 50 employees or an annual turnover of 10 million euros. The sectors include, among others, mechanical engineering, chemicals, food, transport and logistics, as well as energy supply.
  • Critical milestones: The official deadline for BSI registration via the new BSI portal ended on 6 March 2026[1]. Anyone who has missed this obligation so far is already in statutory default and must complete the registration without delay.
  • Extremely strict reporting obligations: In the event of a significant security incident, the law prescribes extremely short response times. You must submit an initial report to the BSI within 24 hours, followed by a detailed analysis after 72 hours.
  • Supply chain protection: The safeguarding also concerns your partners. You must demonstrate that the entire supply chain is secure, since security gaps at service providers fall back directly on you.

Waiting and sitting out this law harbors acute dangers. In addition to significant fines, the main threats are operational shutdowns and the loss of important B2B customers who require a legally compliant supply chain. If you want to determine your business's conformity quickly and easily, the free NIS2 quick check from CAVRIX will help you. With our integrated all-in-one solution for Managed IT and Cybersecurity, this regulatory gap can be closed without you having to build up your own expensive compliance team.

Personally in the Crosshairs: Managing Director Liability Under Paragraph 38 BSIG

With the entry into force of the German NIS2 Implementation Act, the legislator has drastically tightened the rules for IT security in the Mittelstand. The days when cybersecurity could be delegated to the IT department as a pure IT matter are definitively over. Under Paragraph 38 of the BSI Act (BSIG), management is now personally obligated. If you fail to take or monitor the statutory protective measures, you face far-reaching personal liability. This responsibility is legally defined as non-transferable and cannot be shifted onto external service providers or internal specialists.

  • Non-transferable responsibility: As managing director, you must actively approve the IT risk management measures and permanently monitor their concrete implementation in the business. Simply delegating the duties to downstream departments does not legally release you from your responsibility.
  • Risks to your private assets: In the case of culpable failures, you face unlimited personal liability with your private assets in the event of damage. Shareholder resolutions or amendments to the articles of association cannot effectively exclude this legally mandated liability internally.
  • Mandatory further training: In order to be able to competently assess IT risks at all, the law requires you as an executive to regularly participate in cybersecurity training. Under NIS2, ignorance no longer counts as an excuse.

To close these legal gaps in the Mittelstand efficiently and with legal certainty, CAVRIX offers an integrated solution. With our comprehensive services in the areas of Cybersecurity, Managed IT and Compliance, we not only meet the required technical security standards, but also fully relieve you within the scope of NIS2. Through our Command Center, you keep track of the current security status and all compliance-relevant documents of your company at any time via common chat tools such as Microsoft Teams or Slack. In this way, the statutory monitoring obligation becomes effortlessly achievable for you in everyday operations, while your personal liability risk is effectively minimized.

The 10 Minimum Measures: What Paragraph 30 BSIG Specifically Requires

Since the German act implementing NIS2 came into force, there is no longer any grace period for the Mittelstand. Under Paragraph 30 BSIG, you as managing director are legally obligated to implement appropriate, proportionate and effective cybersecurity measures in line with the current state of the art[2]. Since failures can directly lead to your personal liability, you must actively implement the ten statutory minimum areas of risk management and demonstrate compliance with them.

The Most Important Core Areas of Risk Management at a Glance

  • Risk analysis and incident response: You need well-founded procedures for the systematic assessment of your IT risks as well as clear plans for the rapid handling of security incidents[2].
  • Business Continuity Management (BCM): Seamless backup management and tested emergency plans secure the continuation of your operations in a crisis, in order to avert an existence-threatening operational outage[2].
  • Employee training: The entire workforce must be regularly made aware of cyber risks, since human error still represents one of the main gateways for attacks.

The seamless implementation of these complex requirements usually overwhelms the internal resources of the Mittelstand. CAVRIX solves this problem through an AI-native all-in-one platform. We unite your IT infrastructure with proactive protection and worry-free NIS2 compliance. Through the intuitive Command Center, you manage the integrated services for Managed IT, Cybersecurity and Compliance in your daily chat. In this way, you establish a legally secure standard while your IT department is relieved.

The Supply Chain Trap: Why Even Directly Unregulated SMEs Are Affected

Many mid-sized managing directors wrongly believe that the NIS2 directive passes them by because their business does not exceed the official employee and turnover thresholds. This is a dangerous misconception that underestimates the personal liability of management. Large, directly regulated corporations are legally obligated under Section 30 (2) No. 4 BSIG to seamlessly demonstrate the security of their entire supply chain. This obligation for supply chain security is passed on contractually directly to suppliers and service providers. If you cannot provide the required security evidence, drastic consequences threaten your company.

  • Indirect exposure through customer requirements: Your clients increasingly demand detailed evidence of your risk management and your incident reporting in order to secure their own compliance.
  • Threat of exclusion from supply chains: If you cannot present these required security proofs on time, you will be blocked in tenders or lose existing framework agreements as a supplier.
  • Strict standards in IT procurement: Especially in the procurement of IT services, providers must demonstrably meet high protection standards, as they are considered critical gateways for cyberattacks.

This is exactly where CAVRIX comes in. Instead of laboriously hiring your own experts or managing several expensive isolated solutions, CAVRIX bundles Managed IT, Cybersecurity and Compliance into a single, automated platform. Through the integrated Command Center, you keep track of the status of your IT infrastructure at all times and can export security proofs for your major customers at the push of a button. In this way, you secure your market position and meet all the requirements of your partners without having to build up your own compliance team.

The Problem of Separate Silos: Where Traditional IT Providers Fail at NIS2

The new German NIS2 Implementation Act is in force, and with it the grace period for the Mittelstand definitively ends. As managing director or IT manager, you are now personally responsible: in the case of serious failures, the BSI states that you face direct personal liability with your private assets. Many mid-sized companies continue to rely on traditional structures in this critical situation. But this is precisely where the greatest risk lies. If you assign your IT infrastructure, cybersecurity and legal compliance consulting to separate partners, dangerous operational silos arise that prevent a rapid response in an emergency.

  • Interface problems and slow response times: When a security incident occurs, your traditional IT support, the external security provider and the compliance consultant often shift responsibility onto one another. Valuable hours pass before a threat is stopped.
  • High administrative effort in coordination: The continuous monitoring of all systems and requirements demands enormous internal management effort. You spend valuable working time on the laborious coordination of various parties instead of focusing on your core business.
  • Gaps in seamless evidence provision: NIS2 requires audit-proof and seamless documentation of all security measures taken. If your data is scattered across various service providers, the creation of audit-ready reports becomes an enormous risk.

Many traditional IT providers fail at this triple dilemma, because they cannot control compliance and IT operations from a single source. CAVRIX solves this problem and closes the dangerous security gap. We unite Managed IT, Cybersecurity and Compliance in a single, AI-native all-in-one platform. Instead of laboriously coordinating several service providers, you receive a seamlessly integrated system that proactively monitors your IT security, wards off incidents and documents all legal evidence fully automatically for you.

The CAVRIX Approach: Managed IT, Cybersecurity and Compliance United

Classic IT security in the Mittelstand usually suffers from a fundamental problem: unproductive silo thinking. While your previous IT partner handles pure IT operations, another service provider deals with isolated threats, and for legal requirements such as the NIS2 directive there is usually no point of contact at all. With traditional IT providers, you lose valuable time in an emergency through endless coordination. CAVRIX ends this chaos by bundling your Managed IT, proactive 24/7 monitoring through our Cybersecurity, and seamless Compliance into a single platform. For you, this means maximum security from a single source.

  • Fully managed IT operations with integrated security: We take over your entire endpoint management, proactive monitoring and the administration of your IT infrastructure. Your day-to-day business runs stably and protected in the background, while integrated security standards immediately and automatically close every potential security gap.
  • Continuous risk analysis and automatic updates: Cyber threats evolve rapidly. Our platform performs automatic vulnerability analyses around the clock and applies necessary security patches without delay, so that your systems are always up to date without disrupting your operations.
  • Evidence security for upcoming audits: When auditors, customers or authorities demand detailed evidence of your security precautions, our platform delivers audit-proof documents and compliance reports at the push of a button, which legally verify your obligations to seamless risk minimization.

Through our integrated Command Center, you keep full track of the status of your IT infrastructure at any time, without having to possess deep technical expertise yourself. You communicate with your systems directly in everyday chat via Microsoft Teams or Slack. In this way, your mid-sized company effortlessly meets the strict due diligence and training obligations that the law prescribes for managing directors, while at the same time protecting your private assets from drastic personal liability risks.

Control in Real Time: How the Command Center Simplifies Your IT Security

To master the complex requirements of NIS2 and modern IT security, you do not need cluttered dashboards or lengthy coordination with external service providers. With the Command Center, CAVRIX offers an AI-native interface that allows you and your IT managers to control the entire IT infrastructure within your familiar everyday work. Whether via Microsoft Teams, Slack or by email: you simply communicate in natural language. You can query the current security status, view the patch level or request compliance reports, without having to possess deep technical expertise.

  • Direct queries in natural language via familiar channels such as Microsoft Teams, Slack or email
  • Real-time feeds and automated compliance reports at the push of a button to reduce your audit effort
  • Immediate alerting in the event of security incidents to meet the statutory deadlines

This intuitive approach brings maximum transparency to your compliance processes. The Command Center translates technical security data into these easily understandable feeds. In this way, you keep an overview of your NIS2 compliance at all times, without building up your own expensive team of specialists. Every measure, from device management through system patches to policy updates, is documented in an audit-proof manner. This automated evidence provision saves your mid-sized company valuable time during audits and protects you from liability risks.

Another decisive advantage becomes apparent in an emergency. In the event of a serious security incident, swift action is legally required: the Federal Office for Information Security (BSI) demands an initial report within 24 hours of becoming aware. The Command Center sends real-time alerts directly to your preferred chat channel and enables you to react immediately. Because CAVRIX bundles your Cybersecurity as well as Managed IT and Compliance in one platform, threats are not only reported but can be contained immediately. For more in-depth questions, our team is available at info@cavrix.de.

Frequently Asked Questions

What is the German NIS2 Implementation Act and since when does it apply?

The German act implementing the NIS2 directive (NIS2UmsuCG) came into force on 6 December 2025. It tightens the cybersecurity requirements for companies with 50 or more employees or an annual turnover of more than 10 million euros in critical sectors. There are no transition periods, which means that the requirements are legally binding from the first day.

Who is affected by NIS2 in Germany?

Around 30,000 German companies are directly affected that have at least 50 employees or an annual turnover or balance sheet total of more than 10 million euros and are active in important or particularly important sectors. In addition, the law indirectly affects thousands of suppliers, since affected companies must pass on the compliance requirements contractually to their supply chain.

How are managing directors personally liable for NIS2 violations?

Under Paragraph 38 BSIG, management bears the non-transferable responsibility for compliance with the IT security measures. In the case of culpable breach of duty, management is personally and unlimitedly liable with their private assets towards their own company. An exclusion of liability or a delegation of this duty is legally ruled out.

What fines are threatened for violations of the BSIG?

The fines have been drastically increased. Depending on the classification of the company as an important or particularly important entity, breaches of duty carry fines of up to 10 million euros or 2 percent of the worldwide annual turnover of the entire group.

By when did affected companies have to register with the BSI?

The statutory registration deadline for already active affected companies began with the entry into force of the law on 6 December 2025 and ended after three months on 6 March 2026. Companies that have not yet registered in the BSI portal are already in a legal violation and should complete this without delay and, if needed, request support by email at info@cavrix.de.

How does CAVRIX help mid-sized companies with NIS2 compliance?

CAVRIX unites the three essential pillars of IT in an integrated platform: Managed IT, Cybersecurity and Compliance. Instead of having to laboriously coordinate several service providers, you receive a 24/7 Security Operations Center (SOC), continuous risk analyses and automated evidence for audits from a single source. Through the Command Center, you can monitor all activities in natural language.

Sources

  1. secjur.com
  2. secjur.com

Where does your company stand?

30 minutes, free, no commitment. We show you where you stand.